Supplier Privacy Notice

This is the ASSA ABLOY UKI Opening Solutions Group companies’ (“ASSA ABLOY”) privacy notice for individuals at our supplier organisations. This includes contact persons, account managers, representatives, and other personnel of current, former, and prospective suppliers. 

ASSA ABLOY is committed to protecting your personal data. This privacy notice describes:

  • the types of personal data we collect from you when you supply goods and/or services to an ASSA ABLOY company;
    • we generally collect this data directly from you or your organisation. In some cases, we may also obtain information from publicly available sources (such as Companies House, the Central Register of Beneficial Ownership in Ireland, or professional registries), credit reference agencies, or other third parties in connection with due diligence activities.
    • we may also collect your personal data from a public domain source such as LinkedIn or other professional vendor generation sources.
  • how we use that information and why;
  • who we share it with and where;
  • how long we store it for;
  • your rights, including how you can contact us if you have additional questions about the processing of your personal data; and
  • how we can make changes to this notice

 

Depending on which ASSA ABLOY company you have provided your details to, the following will be “data controller" and responsible for the processing of your personal data. 

  • ASSA ABLOY Ltd, a company registered in England and Wales under number 2096505, of School Street, Willenhall, West Midlands, WV13 3PW, United Kingdom
  • P C Henderson Ltd, a company registered in England and Wales under number 01188468, of Durham Road, Bowburn, County Durham, DH6 5NG, United Kingdom
  • P C Henderson (Ireland) Limited, a company registered in the Republic of Ireland under number 026076, of 21 Westlink Industrial Estate, Kylemore Rd, Kylemore, Dublin 10, Ireland. 
  • Carlisle Brass Limited, a company registered in England and Wales under number 02022858, of School Street, Willenhall, West Midlands, WV13 3PW, United Kingdom.
  • Heywood Williams Components Limited t/a Mila Hardware and Heywood Williams Components Ltd t/a ASSA ABLOY Test Centre, a company registered in England and Wales under number 02523354, of School Street, Willenhall, West Midlands, WV13 3PW, United Kingdom.
  • Mila Limited, a company Registered in the Republic of Ireland under number 143406, of 13-18 City Quay, Dublin 2, Dublin, Ireland.
  • ASSA ABLOY Opening Solutions Ireland Limited, a company registered in the Republic of Ireland under number 327918, of 13-18 City Quay, Dublin 2, Dublin, Ireland
  • HKC Security Ltd, a company registered in the Republic of Ireland under number 620390, of Parkway Business Centre, Ballymount, Dublin 24, Dublin, Ireland
  • Security & Risk Communications Limited, a company registered in the Republic of Ireland under number 417550, of Parkway Business Centre, Ballymount, Dublin 24, Dublin, Ireland
  • Senior Architectural Systems Limited, a company registered in England and Wales under number 03909137, of School Street, Willenhall, West Midlands, WV13 3PW, United Kingdom.
  • Sunray Engineering Limited, a company registered in England and Wales under number 01480389, of School Street, Willenhall, West Midlands, WV13 3PW, United Kingdom

 

WHAT PERSONAL DATA DO WE COLLECT?

 We collect and store:

CategoryExamples
Identity and contact informationName, job title, department, employer name, business address, business telephone number, business email address, professional qualifications
Financial and payment informationBank account details, sort codes, IBANs, payment records, invoicing information, tax identification numbers (including VAT numbers)
Due diligence and compliance dataSanctions screening results, politically exposed person (PEP) checks, adverse media screening, anti-money laundering (AML) checks, anti-bribery and corruption assessments, conflict of interest declarations
Contractual and commercial informationCorrespondence and communications records, contract terms, service delivery records, performance assessments, tender and procurement documentation
IT and systems access dataUser credentials (where suppliers access our systems), access logs, IP addresses, device identifiers
Insurance and indemnity informationProfessional indemnity insurance details, public liability insurance certificates

 

HOW AND WHY WILL WE USE YOUR PERSONAL DATA?

We process your personal data for the purposes set out below. For each purpose, we have identified the applicable legal basis under both the UK GDPR and the EU GDPR (as implemented in Ireland). 

PurposeLegal BasisFurther Detail
Managing supplier relationships, including procurement, tendering, contract negotiation, and administrationPerformance of a contract or legitimate interests Where the individual is a party to the contract, Performance of a contract will apply. Where the contract is with the supplier organisation, our legitimate interest in managing the commercial relationship applies.
Processing payments, invoices, and financial transactionsPerformance of a contract or Legal obligationTax, accounting, and financial reporting obligations under UK and Irish law.
Conducting due diligence, including sanctions screening, PEP checks, AML/KYC, and anti-bribery assessmentsLegal obligation or  Legitimate interestsCompliance with sanctions regulations, the Proceeds of Crime Act 2002 (UK), Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 (Ireland), and the Bribery Act 2010 (UK) / Criminal Justice (Corruption Offences) Act 2018 (Ireland).
Compliance with legal and regulatory obligations (including tax, health and safety, and reporting requirements)Legal obligation Various statutory obligations under UK and Irish law, including HMRC requirements and Revenue Commissioners requirements.
Fraud prevention, security, and protection of our business interestsLegitimate interests Our legitimate interest in preventing fraud, protecting our assets, and ensuring the security of our systems and premises.
Managing access to our IT systems and premises (where applicable)Legitimate interests Our legitimate interest in maintaining the security of our systems and physical premises.
Establishing, exercising, or defending legal claimsLegitimate interests Our legitimate interest in obtaining legal advice and protecting our legal rights.

 

WHO AND WHERE WILL YOUR PERSONAL DATA BE TRANSFERRED TO?

We may transfer your personal data for the purposes set out above:

  • To organizations of the ASSA ABLOY Group
  • Third party providers 
    1. Professional advisers: Lawyers, auditors, accountants, insurers, and other professional advisers engaged to provide services to us.
    2. IT service providers: Third-party providers who support our IT infrastructure, including cloud hosting, data storage, and system maintenance.
    3. Payment processors and banks: Financial institutions and payment service providers involved in processing transactions.
    4. Due diligence providers: Third-party screening services used for sanctions, PEP, and AML checks.
  • Regulatory and governmental bodies: Including HMRC, the Revenue Commissioners (Ireland), the Financial Conduct Authority (FCA), the Central Bank of Ireland, law enforcement agencies, and other regulators, where we are required to make disclosures by law or in connection with legal proceedings.
  • Courts and tribunals: Where necessary for the establishment, exercise, or defence of legal claims.
  • When required by law; and/or
  • To a buyer or a potential future buyer of our business.

Some recipients are located in countries outside the UK or EU/European Economic Area (EEA). As in some cases these countries have a lower level of protection than that within the UK or EU/EEA, when transferring personal data to countries outside of the UK or EU/EEA we rely on adequacy decisions, the Data Bridge where applicable or use standard contractual clauses approved by the European Commission or Information Commissioner’s Office to ensure a sufficient level of protection for your personal data. 

We take measures to protect all personal data transferred to a third party, or to other countries, in accordance with applicable data protection laws and as stated above.

 

FOR HOW LONG WILL WE STORE YOUR PERSONAL DATA FOR?

We store personal data for as long as necessary to fulfil the purpose for which the data has been collected, and in accordance with our internal record retention schedule. This means that we delete your personal data when such data is no longer necessary to process a request or to manage our relationship. Statistics which have been anonymised may be saved for longer. 

 

YOUR RIGHTS

In relation to the personal data that we hold about you, you have the right to:

  • Request a copy of your personal data from our records;
  • Ask that we correct or erase your personal data (though this may mean that we cannot process requests or orders, or that your account expires);
  • Ask us to stop processing your personal data (for example as regards the use of the data to improve our website), or restrict how we process it (for example if you deem the data to be incorrect);
  • Request the personal data used to provide you with information you requested, process an order, or manage your account or our relationship in a machine-readable format, which you are entitled to transfer to another data controller; and
  • Withdraw your consent to us processing your data for marketing purposes at any time.

We may not accept a request to erase your personal data where we require it to comply with a legal obligation or in relation to a legal claim.

Requests to exercise your rights should be addressed to privacyuk@assaabloy.com

If you have a complaint regarding our processing of your personal data you are entitled to report this to the Data Protection Commission at dataprotection.ie if you are based in Ireland, or the ICO (Information Commissioner’s Office) at ico.org.uk if you are based in the UK.  If you are located elsewhere, a list of European supervisory authorities can be found at ec.europa.eu

 

HOW CAN WE MAKE CHANGES TO THIS PRIVACY NOTICE?

We may update this privacy notice from time to time in response to changing legal, regulatory or operational requirements. We will notify you of any such changes (including when they will take effect).                                                                                                                  

 

Version 1.0 August 2026

standard
Close